Sublist3r - Fast subdomains enumeration tool for penetration testers

Sublist3r is a python tool designed to enumerate subdomains of websites using OSINT. It helps penetration testers and bug hunters collect and gather subdomains for the domain they are targeting. Sublist3r enumerates subdomains using many search engines such as Google, Yahoo, Bing, Baidu, and Ask. Sublist3r also enumerates subdomains using Netcraft, Virustotal, ThreatCrowd, DNSdumpster, and ReverseDNS.

subbrute was integrated with Sublist3r to increase the possibility of finding more subdomains using bruteforce with an improved wordlist. The credit goes to TheRook who is the author of subbrute.

Usage

Short Form

Long Form

Description

-d

--domain

Domain name to enumerate subdomains of

-b

--bruteforce

Enable the subbrute bruteforce module

-p

--ports

Scan the found subdomains against specific tcp ports

-v

--verbose

Enable the verbose mode and display results in realtime

-t

--threads

Number of threads to use for subbrute bruteforce

-e

--engines

Specify a comma-separated list of search engines

-o

--output

Save the results to text file

-h

--help

show the help message and exit

Examples

To list all the basic options and switches use -h switch:

python sublist3r.py -h

To enumerate subdomains of specific domain:

python sublist3r.py -d example.com

To enumerate subdomains of specific domain and show only subdomains which have open ports 80 and 443 :

python sublist3r.py -d example.com -p 80,443

To enumerate subdomains of specific domain and show the results in realtime:

python sublist3r.py -v -d example.com

To enumerate subdomains and enable the bruteforce module:

python sublist3r.py -b -d example.com

To enumerate subdomains and use specific engines such Google, Yahoo and Virustotal engines

Disclaimer

Any actions and or activities related to the material contained within this Website is solely your responsibility.The misuse of the information in this website can result in criminal charges brought against the persons in question. The authors and www.hack4.net will not be held responsible in the event any criminal charges be brought against any individuals misusing the information in this website to break the law.